Privacy Policy

What we hold, and what we never do

Effective August 9, 2026

The short version

ThreadKnot has four parts and they are not equally private, so this policy treats them separately.

This website counts page views and button clicks, without cookies and without any identifier that could follow you. No accounts, no forms, no ads. The desktop app runs entirely on your own machines, with no account and no telemetry. The mobile app and its notification gateway hold the minimum needed to wake your phone. The hosted relay is optional and paid; it is the only part with an account behind it, and it stores connection metering rather than anything you work on.

We never run ads, never sell or share your personal data, never record your behaviour, and never train any model on your content.

I

Who we are

ThreadKnot is operated by Smith Network Solutions. For the notification relay and for any billing data, Smith Network Solutions is the data controller: the party that decides what is collected and why.

You can reach us about anything in this policy at support@smithnetworksolutions.com.

II

The website

This site is static marketing material. There is no account to create, no form to fill in, no advertising and no third-party tracker. Fonts are served from this site rather than fetched from a font provider, so reading these pages does not report you to a font company.

We do count page views and clicks, using Vercel Web Analytics. We want to know whether people find the download button and which platform they pick. That is the entire ambition.

What the counting does and does not involve

It is first-party and cookieless. Vercel Web Analytics sets no cookie and stores no identifier on your device, so it cannot follow you between sessions or across other websites. There is no profile of you anywhere, because there is nothing to attach one to.

What we see is a count. Specifically:

  • Which page was viewed, and the referring site if there was one.
  • Which buttons were clicked: downloads and the platform chosen, GitHub links, quickstart commands copied, and which FAQ entries were opened.
  • Coarse technical context that arrives with any web request: country, browser, and whether you are on a phone or a desktop.

We never record your screen, replay your session, watch your mouse, or capture anything you type. We do not run heatmaps. The four commitments below apply to this website exactly as they apply to the apps.

You can switch it off with any content blocker, and the site works identically. Nothing on this site depends on being counted.

The site is hosted by Vercel, which also processes standard technical information such as your IP address and browser details in order to serve pages and protect against abuse. That processing is governed by Vercel’s privacy policy.

III

The desktop app

The desktop app runs on your own machines. There is no account to create and no telemetry. Your threads, your code, your prompts and your agent transcripts are written to disk on the machine that ran them and stay there. We never receive them.

You do not have to take our word for it: the source is published, so the claim is checkable line by line in the repository.

Data on your own machines is yours to delete directly. We cannot delete it for you because we never had it.

IV

The mobile app and the notification relay

This is the part of ThreadKnot that genuinely processes data, so it gets the most detail.

A phone cannot be woken by your own computer across a network on its own. Delivering a notification requires a relay and requires Apple or Google to carry the final step. That is the whole reason this component exists.

What the gateway receives

Receives, not stores. The gateway writes no database row and logs no request; a notification exists only for as long as forwarding it takes.

  • Your phone's push token, which is the thing that lets Apple or Google wake that specific device.
  • Identifiers for the server, project and thread the notification came from, which the phone uses to open the right screen. They are opaque to us and resolve to nothing we hold.
  • The notification title and body, for exactly as long as forwarding it takes. Nothing is written to a database and no request is logged. If you turn notification previews off on a device, the text is only which project and what kind of event.

This path is used by every installation with a phone paired to it, including free, local-only and self-built ones, because requiring an account to receive a notification would put a signup in front of the free product.

What we never do

These commitments are the same ones shown inside the mobile app, and they apply to every part of ThreadKnot:

What we never do

  • No advertising, ad identifiers, or ad networks.
  • No selling or sharing of personal data with third parties.
  • No behavioural analytics or session recording.
  • No training of any model on your content.

Who processes data on our behalf

Push delivery uses Apple Push Notification service and Firebase Cloud Messaging, because that is the only way a phone can be woken.

  • Expo

    Carries a notification from the gateway to Apple or Google. It receives the push token, the title and body, and the small routing payload, never an account or installation identifier. Their privacy policy.

  • Apple Push Notification service

    Delivers notifications to iPhones and iPads. Their privacy policy.

  • Firebase Cloud Messaging

    Delivers notifications to Android devices. Their privacy policy.

  • Vercel

    Serves this website and the subscriber console, and handles their technical logs. It is never on the path between a device and your machine. Their privacy policy.

V

The hosted relay, if you subscribe

This subsection applies only if you subscribe to the hosted relay. Nothing in it applies to the free apps. The desktop app, the LAN web UI and the machine-to-machine mesh do not use it and work with no account at all.

The hosted relay gives one of your machines a permanent public HTTPS address, so you can reach it from outside your own network. Your machine dials out to us; nothing listens on your side.

What we store

This is the complete list, taken from the database schema. There is no other table and no other store: no object storage, no log archive, no analytics pipeline.

  • Your account and organisation: an internal id, the identity-provider id, a display name, an email address if your sign-in carries one, and when it was created.
  • One row per machine you enrol: its assigned public hostname label, the machine name you gave it for display, whether it is switched on, its plan and entitlement state, and when it was created and last seen.
  • The public half of each machine's identity key. The private half is generated on that machine and never leaves it.
  • Usage totals: one row per machine per hour holding bytes in, bytes out and the peak number of concurrent streams. That is the entire metering record.
  • A count of devices against your device allowance, as opaque ids. What those devices are and what they may do stays on your own machine.
  • Subscription state from Stripe: customer and subscription ids, status, price, period and trial end. No card data, because Stripe collects payment details directly and we never receive them.

What we do not store

  • No request URLs, methods, headers or bodies.
  • No WebSocket frames, terminal output, screencast frames or file contents.
  • No prompts, agent output, thread contents or repository contents.
  • No content of any kind, in any form, anywhere in the relay path. Nothing from the stream is written to disk.

Metering is byte counters and connection metadata. We count how much moved, never what moved.

Billing

Payments are handled by Stripe (privacy policy), acting as our payment processor. Stripe collects your payment details directly and we never receive or store your card number. We hold your billing email, your subscription status and plan, and the Stripe identifiers that tie them together.

Billing records have to be kept for as long as tax and accounting law requires, even after you close your account, and Stripe retains its own records under its own obligations.

Who else is involved

  • Stripe

    Billing. Receives your billing email if we hold one, and an internal organisation id. Collects payment details directly, so we never receive or store card data. Their privacy policy.

  • Clerk

    Signs you in to the console. Holds your account identity, sign-in events and organisation membership. It never authenticates a machine or a phone, and it is never on the data path. Their privacy policy.

  • LynxLabs

    Hosts the relay server, in the United States. A hosting provider has infrastructure access to the machine it hosts, which is true of any hosted service and worth naming rather than omitting. Their privacy policy.

  • Cloudflare

    DNS only, with no proxy on any record, so no traffic of yours passes through it. Its API is used solely to prove domain control during certificate renewal. Their privacy policy.

  • Let's Encrypt

    Issues the relay's certificate. It is a wildcard, so your individual machine's hostname is never published to the public certificate transparency logs. Their privacy policy.

Switching it off and deleting it

You can switch a machine off from the console at any time. It stops being reachable within about fifteen seconds, its live tunnel is closed, and its public address returns the same generic response an unknown address gets. Turning it back on needs nothing done at the machine.

Deleting a machine from the console removes it and everything that hangs off it, meaning its keys, its usage history and its device counts, and drops it from the relay within about fifteen seconds.

Closing an account entirely is done by writing to support@smithnetworksolutions.com, not by a button, and we will confirm when it is done. We would rather say that than point you at a control that does not exist. Operational log lines on the relay host, which hold byte totals and connect or disconnect events and never content, can outlive the deleted record.

What subscribing does not change

The four commitments apply to paid exactly as they apply to free:

What we never do

  • No advertising, ad identifiers, or ad networks.
  • No selling or sharing of personal data with third parties.
  • No behavioural analytics or session recording.
  • No training of any model on your content.

A subscription buys you a route to your own machines. It never buys us a right to your content.

VI

Agent providers and other third parties

Agent providers you connect on your own machine, such as Anthropic, OpenAI and others, receive whatever you send those agents, under those providers’ own terms. ThreadKnot is not a party to that exchange.

ThreadKnot never collects, stores or transmits the credentials for those services. The app launches the official command line tools you have already installed and signed in yourself.

VII

Your rights and how to use them

Notification pairing is yours to remove from Settings → Account & data in the mobile app. If you subscribe to the hosted relay, a machine and everything recorded against it can be deleted from the console, and closing the account entirely is done by writing to support@smithnetworksolutions.com. Data on your own machines is yours to delete directly.

We answer requests within 30 days. Deletions you make yourself take effect immediately, and a deleted machine drops off the relay within about fifteen seconds. Deletions we perform for you complete within 24 hours of us confirming the request.

Two honest limits. There is no bulk export button today: ask us and a person assembles it. And operational log lines on the relay host, which hold byte totals and connect or disconnect events and never content, can outlive the record they refer to.

If you are in the EEA, the UK or California you may have additional rights, including access to what we hold, correction of anything inaccurate, portability of your data, and the right not to be discriminated against for exercising any of them. You can exercise all of these through the same address, support@smithnetworksolutions.com, and we will not make you jump through a different process to do it.

VIII

How long we keep things

Nothing a notification carries is kept at all: it exists for the duration of the forwarding request and is gone.

Hosted relay records persist while the account and the machine exist. Delete the machine and its keys, usage history and device counts go with it. Close the account and the rest follows.

Two things outlive that by design. Billing records, which tax and accounting law requires us to keep, and which Stripe also retains under its own obligations. And the relay host’s operational log, which holds byte totals and connection events and never content.

IX

Security

Traffic to and from the relay is encrypted in transit. Access is token-gated: a client that cannot present a valid token is refused, and paired mobile devices hold their own revocable credential that we store only as a hash.

Our main security measure is not holding much in the first place. We are not going to claim more than that. No system is perfectly secure, and anyone telling you otherwise is selling something.

X

Children

ThreadKnot is a developer tool and is not directed at children under 13. We do not knowingly collect data from them. If you believe a child has provided us data, write to support@smithnetworksolutions.com and we will delete it.

XI

Changes to this policy

Changes are posted on this page with a new effective date. If we materially change what the relay stores, we will say so plainly at the top of this page rather than slipping it into a paragraph and hoping nobody reads it.

XII

Contact

Questions, requests and complaints all go to the same place: support@smithnetworksolutions.com.

Questions about this document? Write to support@smithnetworksolutions.com.